Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

apostrophecms — Vulnerabilities & Security Advisories 18

Browse all 18 CVE security advisories affecting apostrophecms. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ApostropheCMS is a headless CMS focused on content management for modern web applications. Historically, it has faced vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, with 8 CVEs documented. The platform's modular architecture introduces potential attack surfaces through its rich text editor and custom field types. Notable security characteristics include its PHP-based backend and JavaScript frontend, which may expose it to web application threats. While no major public security incidents have been widely reported, the consistent discovery of vulnerabilities highlights the importance of regular updates and input validation in preventing exploitation.

CVE IDTitleCVSSSeverityPublished
CVE-2026-53609 Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass — apostropheCWE-1321 9.1 Critical2026-06-12
CVE-2026-53608 @apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag — @apostrophecms/seoCWE-79 8.7 High2026-06-12
CVE-2026-53607 @apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header — apostropheCWE-918 3.7 Low2026-06-12
CVE-2026-53606 sanitize-html has an incomplete URI scheme validation that allows javascript: URIs through action, formaction, data, poster, and background attributes — sanitize-htmlCWE-79 5.4 Medium2026-06-12
CVE-2026-45014 Apostrophe Vulnerable to Stored Cross-Site Scripting via Unsanitized User Display Name in Draft Version Tooltip — apostropheCWE-79--2026-06-12
CVE-2026-45013 Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation — apostropheCWE-20 8.1 High2026-06-12
CVE-2026-45012 Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget — apostropheCWE-918 7.6 High2026-06-12
CVE-2026-45011 Apostrophe has stored XSS via javascript: URL in Image Widget Link — apostropheCWE-79 7.3 High2026-06-12
CVE-2026-44990 Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html` — sanitize-htmlCWE-79 9.3 Critical2026-06-12
CVE-2026-42853 @apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input — @apostrophecms/cliCWE-78 6.5 Medium2026-06-12
CVE-2026-40186 ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements — apostropheCWE-79 6.1 Medium2026-04-15
CVE-2026-39857 Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictions — apostropheCWE-200 5.3 Medium2026-04-15
CVE-2026-35569 ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS — apostropheCWE-79 8.7 High2026-04-15
CVE-2026-33889 ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Context — apostropheCWE-79 5.4 Medium2026-04-15
CVE-2026-33888 ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API — apostropheCWE-863 5.3 Medium2026-04-15
CVE-2026-33877 ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint — apostropheCWE-208 3.7 Low2026-04-15
CVE-2026-32731 ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction — import-exportCWE-22 10.0 Critical2026-03-18
CVE-2026-32730 ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware — apostropheCWE-287 8.1 High2026-03-18

This page lists every published CVE security advisory associated with apostrophecms. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.